by symgraph
An native MCP server extension for Ghidra
# Add to your Claude Code skills
git clone https://github.com/symgraph/GhidrAssistMCPGuides for using mcp servers skills like GhidrAssistMCP.
Last scanned: 5/11/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-11T07:43:56.304Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}GhidrAssistMCP is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by symgraph. An native MCP server extension for Ghidra. It has 658 GitHub stars.
Yes. GhidrAssistMCP passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/symgraph/GhidrAssistMCP" and add it to your Claude Code skills directory (see the Installation section above).
GhidrAssistMCP is primarily written in Java. It is open-source under symgraph on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh GhidrAssistMCP against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
A powerful Ghidra extension that provides an MCP (Model Context Protocol) server, enabling AI assistants and other tools to interact with Ghidra's reverse engineering capabilities through a standardized API.
GhidrAssistMCP bridges the gap between AI-powered analysis tools and Ghidra's comprehensive reverse engineering platform. By implementing the Model Context Protocol, this extension allows external AI assistants, automated analysis tools, and custom scripts to seamlessly interact with Ghidra's analysis capabilities.
program_name; use list_binaries Project Path values to disambiguate duplicate filenamesShameless self-promotion: GhidrAssist supports GhidrAssistMCP right out of the box.

Download the latest release:
.zip file (e.g., GhidrAssistMCP-v1.0.0.zip)Install the extension:
Enable the plugin:
Source builds require Java 25 or newer. The included Gradle wrapper pins the supported Gradle release; use it instead of a system Gradle installation.
Clone the repository:
git clone <repository-url>
cd GhidrAssistMCP
Point Gradle at your Ghidra install:
GHIDRA_INSTALL_DIR (environment variable), or pass -PGHIDRA_INSTALL_DIR=<path> when you run Gradle.Build + install:
Ensure Ghidra isn't running and run:
./gradlew installExtension
This copies the built ZIP into your Ghidra install ([GHIDRA_INSTALL_DIR]/Extensions/Ghidra) and extracts it into your Ghidra user Extensions folder (replacing any existing extracted copy).
If you need to override that location, pass -PGHIDRA_USER_EXTENSIONS_DIR=<path>.
Restart / verify:
Open the Control Panel:
Configure Server Settings:
localhost8080The Configuration tab allows you to:
GhidrAssistMCP can also be started from Ghidra's analyzeHeadless launcher. This is useful when you want MCP access to a program loaded in headless Ghidra without opening the CodeBrowser UI.
First, build and install the extension so Ghidra can load the compiled classes and bundled dependencies:
cd /path/to/GhidrAssistMCP
export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1_PUBLIC
./gradlew installExtension
Set paths for your Ghidra install and extracted user extension. On Linux, Ghidra user extensions usually live under ~/.config/ghidra/<ghidra_profile>/Extensions:
export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1_PUBLIC
export GHIDRA_USER_EXTENSIONS_DIR="$HOME/.config/ghidra/ghidra_12.1_PUBLIC/Extensions"
export GHIDRASSISTMCP_EXT="$GHIDRA_USER_EXTENSIONS_DIR/GhidrAssistMCP"
Import a binary and start the MCP server as a headless pre-script:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
-import /path/to/binary \
-scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
-preScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080"
For a binary that is already imported into the project, use -process instead:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
-process binary_name \
-scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
-preScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080"
To keep a headless MCP session open after analysis completes, run the server as a post-script with wait mode:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
-process binary_name \
-scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
-postScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080" "wait=true"
MCP clients can connect to:
SSE: http://127.0.0.1:8080/sse
SSE messages: http://127.0.0.1:8080/message
Streamable HTTP: http://127.0.0.1:8080/mcp
The headless MCP server runs inside the analyzeHeadless JVM and uses the loaded currentProgram. The server holds a program consumer while it is running so MCP requests do not race against program database closure. Use wait=true when you want analyzeHeadless to stay open for interactive MCP clients. A harness can also pass completion_file=/workspace/control/session.complete; creating that file closes the MCP server cleanly and lets Ghidra save and exit normally.
Disposable static-analysis labs may pass tool_profile=agent_lab. This enables sandbox-local program export while arbitrary path import and Ghidra scripts remain disabled because they can expose process secrets or spawn processes. The harness owns artifact imports. Unknown profiles are rejected.
GhidrAssistMCP provides 49 tools organized into categories. Several tools use an action-based API pattern where a single tool provides multiple related operations.
| Tool | Description |
|---|---|
get_binary_info |
Get basic program information (name, architecture, compiler, etc.) |
list_binaries |
List all open programs across all CodeBrowser windows, including Project Path values for unambiguous program_name targeting |
open_program |
List/open project programs in CodeBrowser, with optional analysis prompt suppression and analysis-after-open task submission |
close_program |
Close an open CodeBrowser program; changed programs require save=true or ignore_changes=true |
import_file |
Import a host file into the current Ghidra project and optionally open it (disabled by default) |
project_files |
List or delete files/folders in the active Ghidra project; deletion requires confirm=true |
scripts |
List/read/create/delete/run Ghidra scripts (disabled by default) |
assemble_code |
Assemble instruction text at an address and optionally patch it into program memory |
patch_bytes |
Patch raw bytes in program memory at a given address |
export_program |
Export the current program to disk (binary or original_file) (disabled by default) |
Security-sensitive tools:
import_file,scripts, andexport_programare disabled by default because they interact with the host filesystem or execute script code. Enable them explicitly in the plugin configuration UI when needed.project_filesdeletes entries from the active Ghidra project database, not the original imported host files, and requiresconfirm=true.
| Tool | Description |
|---|---|
analysis_options |
List/set/reset Auto Analysis options and save/apply/list/delete option presets for the current program |
analyze_program |
Run Auto Analysis on the current program or all open programs; supports full re-analysis, pending-changes analysis, address ranges, and option overrides |
analysis_control |
Query Auto Analysis status or request cancellation of queued analysis tasks |
| Tool | Description |
|---|---|
get_functions |
List functions with optional pattern filtering and pagination |
search_functions_by_name |
Find functions by name pattern |
get_function_statistics |
Comprehensive statistics for all functions |
analyze_function |
Get detailed function information (signature, variables, etc.) |
get_current_function |
Get function at current cursor position |
| `get_function_s |